Full Report
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
Analysis Summary
# Incident Report: Disruption of QTFY State-Sponsored Botnet (QScan/QTRouter)
## Executive Summary
The U.S. Department of Justice and FBI announced the disruption of two major hacking platforms, **QScan** and **QTRouter**, operated by the Chinese state-sponsored group **QTFY**. The threat actor utilized a massive global botnet of compromised IoT devices to obfuscate cyber espionage activities targeting U.S. critical infrastructure, government agencies, and academic research institutions. The operation successfully seized control of the infrastructure used to conceal the origin of PRC-linked attacks.
## Incident Details
- **Discovery Date:** Approximately August 2025 (Collaboration between FBI and Lumen began "about a year ago")
- **Incident Date:** Active since May 2018
- **Affected Organizations:** NASA, Federal Reserve, Department of Energy, DOJ, HHS, NIH, U.S. Senate, and various academic research communities.
- **Sector:** Government, Critical Infrastructure, Academia, Healthcare.
- **Geography:** United States (Target); Global (Botnet infrastructure nodes).
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing since May 2018.
- **Vector:** Exploitation of zero-day and N-day vulnerabilities in edge devices and IoT hardware.
- **Details:** Specific exploitation of Ivanti CSA appliances (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) and older vulnerabilities in Fortinet, Citrix, and Microsoft Exchange.
### Lateral Movement
- The actors used the **QTRouter** obfuscation network to blend in with legitimate local traffic, allowing them to move through victim networks while appearing as internal or local geolocated endpoints.
### Data Exfiltration/Impact
- **Impact:** Systematic theft of sensitive data from U.S. federal agencies and research institutions. The platform served as a "digital quartermaster" for the MSS and PLA to conduct untraceable espionage.
### Detection & Response
- **Detection:** Identified by Lumen Black Lotus Labs through long-term tracking of the "QTFY" group and Nanjing Xinjiuwei Network Technology Company.
- **Response:** In August 2026, the DOJ and FBI executed a court-authorized disruption, seizing domains and infrastructure associated with the QScan and QTRouter platforms.
## Attack Methodology
- **Initial Access:** Scanning for and exploiting vulnerable IoT devices and enterprise edge software (VPNs, CMS, Mail servers).
- **Persistence:** Implementation of custom OpenWrt software on compromised routers and the use of secondary-level control servers.
- **Defense Evasion:** Use of **Clash** to chain proxy nodes, mixing malicious traffic with legitimate commercial proxy services to hide the Chinese origin.
- **Discovery:** Automated reconnaissance using the **QScan** platform to identify vulnerabilities in target networks.
- **Lateral Movement:** Obfuscated traffic via local botnet nodes to bypass geo-fencing and anomaly detection.
- **Impact:** Strategic espionage and potential for DDoS attacks via the QTBotnet controller.
## Impact Assessment
- **Financial:** Costs associated with multi-year federal investigations and remediation of compromised government systems.
- **Data Breach:** High volume of sensitive government, military, and scientific research data compromised.
- **Operational:** Disruption of critical infrastructure security posture.
- **Reputational:** Significant breach of trust regarding the security of IoT devices and edge infrastructure in federal networks.
## Indicators of Compromise
### Network Indicators
- qt-proxy[.]org
- mq-task.qt-proxy[.]org
- mq-result.qt-proxy[.]org
- mq-task.qt-team[.]com
- mq-result.qt-team[.]com
- www.qtproxy[.]xyz
- securelink.qtproxy[.]xyz
### Behavioral Indicators
- Traffic originating from residential or small-office/home-office (SOHO) IP addresses attempting to access sensitive administrative interfaces.
- Presence of "Clash" proxy configurations on non-standard network devices.
## Response Actions
- **Containment:** Seizure of C2 domains and management platforms by the FBI.
- **Eradication:** Identification and notification of domestic and international victims whose IoT devices were part of the QTRouter botnet.
- **Recovery:** Ongoing patching of N-day vulnerabilities (Fortinet, Citrix, Log4j) across affected sectors.
## Lessons Learned
- **IoT Vulnerability:** Low-power IoT devices remain a primary target for building large-scale obfuscation networks.
- **Legacy Vulnerabilities:** The continued use of 2018-2021 era vulnerabilities (e.g., CVE-2018-13379) highlights a critical failure in patch management across sensitive sectors.
- **Attribution:** Private-public partnerships (Lumen/FBI) are essential for tracking state-sponsored "quartermasters" who supply infrastructure to multiple intelligence agencies.
## Recommendations
- **Edge Device Auditing:** Regularly audit and update firmware for all SOHO routers and IoT devices connected to corporate or government networks.
- **Geo-Blocking Limitations:** Recognize that threat actors can bypass geo-blocking by using local compromised proxies; implement behavior-based analytics rather than just location-based.
- **Zero-Trust Architecture:** Move toward a zero-trust model where the "location" of a request (even if local) does not inherently grant trust.